Repository navigation
Expand file tree
/
Copy pathcompose.env.example
More file actions
120 lines (102 loc) · 5.24 KB
/
Copy pathcompose.env.example
File metadata and controls
120 lines (102 loc) · 5.24 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
# Compose project env — NOT the gateway process .env.
# cp compose.env.example compose.env
# docker compose --env-file compose.env up -d --build
# Do not copy this to `.env` (that file is for `bun run dev` via `.env.example`).
# Postgres image bootstrap (must match the admin DSN below)
POSTGRES_USER=sprout_admin
POSTGRES_PASSWORD=change-me-admin
POSTGRES_DB=postgres
# Canonical admin DSN for the gateway (URL-encode special chars in the password).
# Keep user/password/db in sync with POSTGRES_* above.
# Gateway ensures SPROUT_PG_USER on boot (needs CREATEROLE or superuser).
SPROUT_PREVIEW_POSTGRES_URL=postgres://sprout_admin:change-me-admin@postgres:5432/postgres
# Hostname/port preview app+seed containers use for PGHOST/PGPORT on SPROUT_POSTGRES_NETWORK.
# Bundled stack: leave as postgres. External Postgres: set to that service's DNS name.
SPROUT_PG_HOST=postgres
SPROUT_PG_PORT=5432
# Static preview credentials injected into app/seed containers (v0.1 spec)
SPROUT_PG_USER=sprout_preview
SPROUT_PG_PASSWORD=change-me-preview
# Docker network names (single source for compose `name:` and gateway env).
SPROUT_TRAEFIK_NETWORK=sprout-traefik
SPROUT_POSTGRES_NETWORK=sprout-postgres
# Preview mail (Mailpit) — optional; unset group = no mail env injected.
# SPROUT_MAIL_HOST=mailpit
# SPROUT_MAIL_PORT=1025
# SPROUT_MAIL_USER=
# SPROUT_MAIL_PASSWORD=
# SPROUT_MAIL_SECURE=
# SPROUT_MAIL_NETWORK=
# SPROUT_MAIL_UI_URL=
# SPROUT_MAIL_FROM_DOMAIN=preview.invalid
# Registry pull credentials (empty = anonymous). Prefer AUTHS_JSON for multi-registry.
# SPROUT_REGISTRY_AUTHS_JSON={"ghcr.io":{"username":"u","password":"p"}}
SPROUT_REGISTRY_USER=
SPROUT_REGISTRY_PASSWORD=
SPROUT_REGISTRY_AUTHS_JSON=
# Traefik router TLS labeling (optional). Empty entrypoints = HTTP-only labels
# (no tls/entrypoints/certresolver). Set ENTRYPOINTS to enable HTTPS; CERTRESOLVER
# is optional with that. Example for Coolify-managed proxy: https + letsencrypt
# SPROUT_TRAEFIK_ENTRYPOINTS=https
# SPROUT_TRAEFIK_CERTRESOLVER=letsencrypt
# Opt-in wildcard mode: routers declare tls.domains for their suffix so the
# DNS-01 resolver serves one wildcard per preview suffix (zero orders/deploy).
# Requires CERTRESOLVER (DNS-01 only, never HTTP-01). See docs/operator-deploy.md
# § "Wildcard preview certificate (DNS-01)".
# SPROUT_TRAEFIK_WILDCARD_TLS=false
# Traefik forwardAuth (optional SSO gate). Both must be set together (or both
# empty). MIDDLEWARES is a single Traefik middleware name (no commas). Gateway
# emits middleware definition + router attachment as Docker labels — no Traefik
# file/static config. Address must be Traefik-reachable.
# SPROUT_TRAEFIK_MIDDLEWARES=voidauth
# SPROUT_FORWARDAUTH_ADDRESS=https://auth.example.com/api/authz/forward-auth
# Per-preview access gate (optional; enables preview.auth link).
# Both required together or both empty. preview.auth basic needs no gateway env.
# SPROUT_PREVIEW_AUTH_SECRET=
# SPROUT_PREVIEW_AUTH_ADDRESS=http://gateway:7331/v1/internal/preview-auth
# Read-only preview dashboard (optional; off by default). When enabled the
# gateway serves GET /dashboard with HTTP basic auth — operator only, since
# the page lists preview hostnames. Enabling without USER/PASSWORD fails boot.
# HOST optionally hides the page from every other Host (serve it behind your
# own proxy hostname and certificate).
# SPROUT_DASHBOARD_ENABLED=false
# SPROUT_DASHBOARD_HOST=
# SPROUT_DASHBOARD_AUTH=basic
# SPROUT_DASHBOARD_USER=
# SPROUT_DASHBOARD_PASSWORD=
# Optional: pin control-plane SQLite / admin token file (compose defaults shown)
# SPROUT_STATE_DB_PATH=/data/sprout.db
# SPROUT_ADMIN_TOKEN_PATH=/data/admin-token
# Anonymous install telemetry (published image only). Both empty = no
# destination, nothing sent. Set both to opt a from-source build into
# reporting; the ghcr.io image already carries the maintainer destination.
SPROUT_TELEMETRY_ENDPOINT=
SPROUT_TELEMETRY_AUTH=
# Operator-owned trace export (opt-in OTLP/HTTP). Empty endpoint = off.
# Endpoint is the traces URL used verbatim; headers are comma-separated
# name=value pairs sent on every export request.
# SPROUT_OTLP_ENDPOINT=
# SPROUT_OTLP_HEADERS=
# Host ports published by compose (override for e2e — see e2e/compose.e2e.env)
SPROUT_GATEWAY_HOST_PORT=7331
TRAEFIK_HTTP_PORT=8880
# Operator bootstrap token — omit, comment out, or leave blank to auto-generate
# SPROUT_ADMIN_TOKEN=
# Forge API for sweep. Kind is inferred per repo (github.com / gitlab.com).
# Tokens may be blank at boot; set before sweep runs. Use both for mixed gateways.
SPROUT_GITHUB_TOKEN=
SPROUT_GITLAB_TOKEN=
# Optional self-managed GitLab: host=gitlab (e.g. git.example.com=gitlab)
# SPROUT_FORGE_HOSTS=
# Preview governance: the self-serve local stack ships safe (7d TTL on).
# Gateway code defaults are off (unbounded); compose sets 7d so a new
# operator is safe without configuring anything. Manifest preview.ttl /
# preview.idle_teardown override these per repo; off at either level disables.
SPROUT_PREVIEW_TTL=7d
# SPROUT_PREVIEW_IDLE_TEARDOWN=off
# SPROUT_MAX_PREVIEWS_PER_REPO=off
# SPROUT_MAX_PREVIEWS=off
# Connection budget: expected per-preview connections vs the instance ceiling.
# Measured: ~12 idle connections per preview app at default pool sizes.
# SPROUT_PREVIEW_MAX_DB_CONNECTIONS=12
# SPROUT_POSTGRES_MAX_CONNECTIONS=100